Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Re: Automating Auditing of Directory Service Objects

Reply
Thread Tools Display Modes

Re: Automating Auditing of Directory Service Objects

 
 
Ace Fekay [MVP - Directory Services, MCT]
Guest
Posts: n/a

 
      05-19-2010

On Wed, 19 May 2010 06:42:49 -0700 (PDT), Neil
<> wrote:

>Hi. Is there a way to automate the deployment of Auditing settings to
>the OU's in AD? I only have a handful so it doesn't have to be TOO
>efficient. These have to be deployed automatically (via script,
>command line or whatever) if at all possible.
>
>Is this possible? If so, where can I start looking?
>
>Thanks!


If auditing of Directory Service Objects, that would be set on the
domain controllers, either individually or using a GPO and linked to
the Domain Controllers OU.

There are also purchasble third party auditing tools that are more
elaborate.

Have you tried using a GPO yet for this purpose? If so, have you had
any problems?

Ace

This posting is provided "AS-IS" with no warranties or guarantees and confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among responding engineers, and to help others benefit from your resolution.

Ace Fekay, MVP, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services

If you feel this is an urgent issue and require immediate assistance, please contact Microsoft PSS directly. Please check http://support.microsoft.com for regional support phone numbers.
 
Reply With Quote
 
 
 
 
Ace Fekay [MVP - Directory Services, MCT]
Guest
Posts: n/a

 
      05-24-2010
On Wed, 19 May 2010 23:55:30 -0700 (PDT), Neil
<> wrote:

><snip>
>>
>> If auditing of Directory Service Objects, that would be set on the
>> domain controllers, either individually or using a GPO and linked to
>> the Domain Controllers OU.
>>
>> There are also purchasble third party auditing tools that are more
>> elaborate.
>>
>> Have you tried using a GPO yet for this purpose? If so, have you had
>> any problems?
>>
>> Ace
>>
>> This posting is provided "AS-IS" with no warranties or guarantees and confers no rights.
>>
>> Please reply back to the newsgroup or forum for collaboration benefit among responding engineers, and to help others benefit from your resolution.
>>
>> Ace Fekay, MVP, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
>> Microsoft Certified Trainer
>> Microsoft MVP - Directory Services
>>
>> If you feel this is an urgent issue and require immediate assistance, please contact Microsoft PSS directly. Please checkhttp://support.microsoft.comfor regional support phone numbers.

>
>Thanks for the reply! I know you can enable the auditing via GPO and
>the 'Audit Directory Service Access' policy setting (to enabled). In
>addition to this, you then have to enable auditting on the objects you
>want (like setting it to audit any failure for 'UserX' on the OU 'Y'.
>
>So a better way to ask my question would be;
>
>"Is there any way to programmatically set SACLs on Directory Service
>objects?"
>
>Thanks!


That would be a question better suited for the programming forums
(such as VB and ADSI scripts).

A couple of the folks that respond in this newsgroup and forums are
familiar with this area. Sorry I can't better help you in this area.

Ace
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows server 2000 strange crash Rick Windows Server 14 04-21-2010 12:04 PM
Re: Active Directory problems/dcdiag error kj [SBS MVP] Windows Server 4 03-24-2010 09:19 PM
Re: Active Directory problems/dcdiag error kj [SBS MVP] Windows Small Business Server 3 03-24-2010 09:19 PM
Event ID 566 - Directory Service Access Lee Windows Server 2 03-24-2010 01:16 PM
Re: Incorrect server name Ace Fekay [MCT] Windows Server 4 10-28-2009 02:17 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59